LIVE
1,218 regulations trackedEU AI Act — amendment 03.14India DPDP — §17 draft rulesColorado CPA — enforcement 2026-042.1M DSARs automatedSOC 2 Type II renewedSingapore PDPA advisory1,218 regulations trackedEU AI Act — amendment 03.14India DPDP — §17 draft rulesColorado CPA — enforcement 2026-042.1M DSARs automatedSOC 2 Type II renewedSingapore PDPA advisory
FaceOFF.world
Regulations & frameworks

Every regulation, mapped to your controls.

The copilot tracks 1,218 regulations across 38 jurisdictions and cites the exact clause behind every control. Pick a law to see the products that keep you compliant.

1,218
regulations tracked
38
jurisdictions
8
audit frameworks

Europe & UK

3

GDPR

European Union
GDPR

The baseline for lawful processing, data-subject rights, records of processing, and breach duties across the EU.

Lawful basisArt. 15–22 rightsArt. 30 RoPAArt. 35 DPIA

UK GDPR & PECR

United Kingdom
UK-GDPR

UK GDPR mirrors EU rights; PECR governs cookies, tracking, and electronic marketing.

Cookie consentMarketing rulesSubject rights

ePrivacy Directive

European Union
ePR

The “cookie law” — prior consent for non-essential storage and access on a user’s device.

Prior consentTracker disclosure

Americas

4

CPRA / CCPA

California, USA
CPRA

Consumer rights to know, delete, correct, and opt out of sale or sharing of personal information.

Opt-out of saleAccess & deleteSensitive PI limits

US State Privacy Laws

VA · CO · CT · UT · TX
US-STATE

A growing patchwork (VCDPA, CPA, CTDPA and more) with opt-outs, appeals, and assessments.

Universal opt-outRight to appealData assessments

LGPD

Brazil
LGPD

Brazil’s general data protection law — legal bases, data-subject rights, and DPO duties.

Legal basesSubject rightsDPO reporting

PIPEDA

Canada
PIPEDA

Consent-based handling of personal information with access and accountability obligations.

Meaningful consentAccess requestsAccountability

Asia-Pacific

3

India DPDP Act

India
DPDP

Notice-and-consent framework with data-principal rights and duties for significant data fiduciaries.

Notice & consentPrincipal rightsConsent managers

PDPA

Singapore
PDPA

Consent, purpose limitation, and mandatory breach notification for personal data.

ConsentPurpose limitsBreach notice

Privacy Act (APPs)

Australia
AU-PA

The Australian Privacy Principles cover collection, use, cross-border disclosure, and access.

APP complianceCross-border rulesAccess & correction

Sector & emerging

2

HIPAA

US Healthcare
HIPAA

Protects PHI with privacy and security rules and business-associate agreements across vendors.

PHI safeguardsBAAsMinimum necessary

EU AI Act

European Union
AI-ACT

Risk-tiered obligations for AI systems, including impact assessments and documentation.

Risk classificationImpact assessmentTechnical docs
Don’t see your regulation? The research team adds new laws and amendments weekly — ask the copilot to map any framework to your controls.

Which regulations apply to you?

Run a free scan and the copilot maps your data and site against every regulation above — with citations.

Request demo →
SOC 2 Type II·ISO 27001·GDPR·HIPAA-ready